Trust & Security
Last Updated: June 2026
About This Page
This page is maintained by the SatoshiDrip team to answer common security and privacy questions about SatoshiDrip. It describes the controls currently enabled in the app and our current data-handling practices. It is editable project content and is not a certification or independent audit.
Authentication & Access
- Sign-in supports email and password and Google OAuth.
- Passwords are hashed and stored by our managed authentication provider; we never see your plaintext password.
- Session tokens are scoped to your browser and used to authorize requests on your behalf.
- Sensitive actions (withdrawals, account changes) require an active authenticated session.
Platform & Hosting
- The app is hosted on the Lovable platform with managed serverless infrastructure.
- Data is stored in a managed Postgres database with row-level security policies that scope records to the owning user.
- Server-side privileged operations run in trusted server functions and are not exposed to the browser.
Data We Collect
- Account data: email, username, referral code, and authentication identifiers.
- Activity data: claims, ad views, offerwall completions, coupon redemptions, withdrawals, and balances needed to operate the rewards system.
- Technical data: standard request metadata (IP address, user agent) used for abuse prevention and rate limiting.
Subprocessors & Integrations
SatoshiDrip integrates third-party services to operate the platform. These providers process the minimum data required for their function:
- Managed auth, database, and hosting provider (Lovable Cloud).
- Offerwall and survey partners (e.g. CPX Research, BitcoTasks).
- Advertising partners for the Paid-to-Click and banner ad slots.
- Cryptocurrency payout processor for withdrawals (e.g. FaucetPay).
- Bot protection (Cloudflare Turnstile).
Abuse Prevention
- Bot protection challenges (Turnstile) gate sensitive endpoints.
- Server-side cooldowns and atomic guards prevent duplicate claims and race conditions on rewards.
- Suspected fraud (multi-accounting, automation, VPN abuse) may result in reward reversal or account suspension as described in our Terms.
Data Retention & Deletion
Account and activity records are retained while your account is active and for a reasonable period afterward for fraud prevention, accounting, and legal compliance. To request deletion of your account, contact us using the address below.
Privacy Requests
You can request access to, correction of, or deletion of your personal data by contacting us. We will respond within a reasonable timeframe consistent with applicable law.
Security Contact
To report a suspected vulnerability or security concern, contact the SatoshiDrip team via the contact channel listed on the site. Please include enough detail to reproduce the issue and do not test against other users' accounts.
Shared Responsibility
- Lovable provides the underlying platform, managed database, and authentication infrastructure.
- SatoshiDrip configures the app, defines access rules, and operates the rewards system.
- You are responsible for keeping your credentials secure and using the platform in accordance with our Terms.